Findings & intelligence

Use the security catalog

Look up vendor advisories, CWE weaknesses, and software end-of-life records in the Secorvia Security Catalog.

Reviewed

Before you start

Catalog availability depends on the sources configured for the deployment. The interface explicitly distinguishes unpopulated catalogs from search filters that match nothing.

Choose a catalog

Open Security Catalog and select Vendor Advisories, Weaknesses (CWE), or End of Life. Use vendor advisories to research a published issue, CWE to understand a weakness category, and end-of-life data to review a product release cycle.

Search vendor advisories

Search the advisory text and filter severity. Open a record to inspect Advisory ID, Source, CVE IDs, affected packages, references, publication/modification dates, and whether the advisory was withdrawn.

Look up a weakness or product cycle

Search weaknesses by their available identifiers or descriptions. For End of Life, the product-name filter uses an exact match; for example, use the product identifier ubuntu. Review cycle, release date, EOL date, support end date, and latest version.

Interpret missing data correctly

The current app reports that the CWE catalog has no automated ingestion source registered yet. An empty CWE view is therefore expected on an unpopulated deployment. Advisory and EOL catalogs depend on their synchronization workers. Use the record’s references before making an upgrade decision.

Where you are now

You can locate supporting security information and distinguish an empty source from a clean assessment.

WHEN SOMETHING LOOKS OFF

A few things to check

No cycles found

Use the exact product identifier or clear the product filter.

No vendor advisories or EOL records

Ask the platform administrator to check the corresponding source synchronization.

PUT IT INTO PRACTICE

Make your next move in Secorvia.

Open the app and follow along with your own organization.

Open Secorvia